Gamma's September partner newsletter landed on 30 September with two things on the same page. The first is that Gamma's Global Communications Enablement platform "now supports TLS and SRTP, providing enhanced security for SIP communications through encrypted signalling and media". The second is that Gamma has been named the third most trustworthy Software and Telecommunications company in the world.
What has been announced is not caller authentication, it is not STIR/SHAKEN, and it has nothing whatsoever to do with knowing who is ringing you. It is transport encryption: the signalling that sets a call up travelling over TLS instead of in the clear, and the audio travelling as SRTP instead of as plain RTP, which anybody with a tap and a copy of Wireshark can turn back into a recording in roughly the time it takes to make a cup of tea. It is the right thing to do, it has always been the right thing to do, and the only question is why it is being announced in the fourth quarter of 2026.
We turned TLS and SRTP on for outbound calls in January 2013, and by that December the capability was there on inbound too, on every number we deliver over SIP, which I wrote up at the time in TLS/SRTP and why you need them!. It has been free on every call since. Not a security bundle, not a premium tier, not a conversation with your account manager. Free, because charging somebody extra not to be intercepted isn't a product, it's a toll.
That was thirteen years ago. In the same few weeks, Jessops, HMV and Blockbuster all went into administration. Blockbuster, remember them? Thirteen years in which this has been so ordinary here that nobody internally thinks of it as a feature, it has never appeared on a price list, and the last time I wrote about it at any length I was arguing with people who thought it was a waste of money.
One platform is not a portfolio
The newsletter's standfirst promises "secure upgrades on our global voice portfolio". The item underneath it covers one platform. Global Communications Enablement is Gamma's international voice platform for service providers, launched in April 2025, and it is the only thing named in the announcement.
Gamma did not build it. Its own account of the launch says Coolwave, the Irish wholesale business it bought, "brought their own network capabilities, session border controllers (SBCs) and data centres", and that GCE is "just a portfolio name to bring all of those to light". What was actually bought is set out in Gamma's 2024 half-year report: net assets acquired of £7.5m, of which tangible fixed assets were £0.1m and technology intangibles £6.0m. Gamma's own accounting policy says what that technology line consists of: "software licences purchased from third parties" and "rights over network interface identifications". A hundred thousand pounds of kit and six million pounds of permission to use other people's.
One platform is not a portfolio. What the rest of it does, I do not know, and neither does anybody who read that newsletter, which is a peculiar thing to be true of a security announcement. Which products, and since when? Gamma has not said.
In 2017 I wrote a post called Encryption is "Pointless"!, named after what somebody in this industry had put to me in writing. "We know most other wholesalers don't offer it," I wrote then. "We also know 'me too' doesn't offer it so their shiny suits will proclaim that the market doesn't want it." "Me too" was not a category. It was a company, and people did ask me which one. The market didn't want it because almost nobody was selling it, and almost nobody was selling it because the crypto licence on a big vendor's magic box costs an order of magnitude more than the basic one, which is a point I made again last October and which nothing since has done anything to disturb. Why can't anybody just say that out loud? The licence was expensive, we didn't buy it, our customers' audio went across the public internet in the clear for as long as it took us to give a shit.
Unencrypted media is never abstract. It is readable by anybody in the path, and the audio is somebody ringing their GP, somebody ringing a solicitor, somebody ringing a helpline they would rather nobody knew they had rung. That is what is in the packets, and it is why I have been banging this drum for thirteen years while being told the market doesn't want it.
The same joke, twice
If this were the only thing that had arrived late I would put it down to a bad quarter.
In September 2024 I wrote Resilience is not a magic button, and the ask in it was not complicated: "we lean so heavily on DNS and encourage all customers to use fully qualified domain names (FQDNs) rather than direct IP addresses". Use a name and you have multiple A records, short-lived records you can update straight off your monitoring, SRV and NAPTR. "SRV is the daddy here," I wrote, "because it also enables all of the aforementioned yet gives a pre-configured failover and load-balancing schedule." A name is how the internet tells you where something is. It is the difference between a supplier being able to move your traffic around a problem and a supplier having to ring you up about it.
Gamma's own technical service description for SIP Trunks said, for years and in terms, that DNS capability, including SRV and A record lookup, was not supported, and that the customer's equipment was identified instead by a static public IP address assigned by the customer's ISP. That document sits in public, as published on the Crown Commercial Service's G-Cloud marketplace, where anybody can go and read it. Gamma's own developer site makes the same point rather more briefly: the SIP Trunks API specification published there gives you exactly one variable for telling Gamma where your equipment is, and it is an IP address.
Names did eventually arrive, on the carrier side, in the early part of last year, and the document explaining how to use one ran to thirteen pages. Thirteen pages, for a DNS lookup. Whether the same is now true of a SIP trunk, I could not tell you, and that is the second time in one post that the answer to "which products, and since when" is not written down anywhere a customer can read it.
The domain name system was specified in 1983. It is older than the company and older than most of the people who will read this. So the complaint is not that Gamma does not support names, it is the forty-two years it took. Same magic box, same licence economics, same decade of asking, same small announcement when it finally lands. Twice is a pattern.
What a buyout house is actually buying
On 1 September Gamma's board recommended an offer from Epiris, taking the company private, expected to complete in the first half of next year. I wrote about it at the time: a fund does not buy a business in order to own it, it buys one in order to sell it again, and the price it paid has to come back out of the business through price, through cost, or through both.
So look at what has actually shipped and ask where else the return could come from. Transport encryption on one platform in the fourth quarter of 2026. Hostnames on the carrier side four decades after the specification. An international voice business whose acquired value was, on Gamma's own numbers, four fifths licences and rights. Whatever Epiris is paying a premium for, on this evidence it is not the pace of development, because nobody underwrites a return on a roadmap that is delivering 2013 on a good day. Which leaves the price list and the cost base. The cost base is people, and the price list is you.
Then there is the other half of that page
Gamma has been ranked number three in the world for Software and Telecommunications in Newsweek's World's Most Trustworthy Companies 2026, produced with Statista. It is a perception study. It measures belief, not truth.
Newsweek's own ranking page carries the line "Are you on the list? Click here to learn more about the licensing options", and that link leads to Statista's award portal, where the logo, the certificate and the trophy are licensed products. Being trusted is free. The trophy is not.
A trust survey measures what people outside a building think is going on inside it, and it cannot measure what is actually going on inside it, because not one of the people surveyed had any way on earth of knowing whether the signalling was encrypted. So you can be the third most trustworthy telecommunications company in the world, on a methodology that is entirely honest about measuring belief, and announce on the same page that the audio was crossing the public internet in the clear until last month.
Same email. Sent to partners.
Four questions
They aren't for Gamma. They've simply had the misfortune of being the most recent example in my inbox, but they are not alone at all. Ring whoever carries your traffic and ask: does my traffic run over TLS with SRTP, right now, on every call in and every call out? Since when? Does it cost extra? And can I point my equipment at a name instead of an address?
If the answer to the third one is yes, you already have the answer to the first two. If the answer to the fourth one is no, ask what else is still waiting for a licence somebody didn't buy.